The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Configure default log storage pools

Prev Next

Configure log storage pools to send event data to the Trellix Enterprise Security Manager - Enterprise Log Manager.

Important

Devices do not send events to the Trellix Enterprise Security Manager - Enterprise Log Manager until after their aggregation time periods have expired.

  1. From the Trellix ESM dashboard, click menu.png and select More Settings.

  2. On the system navigation tree, select the device and click Settings.png.

  3. Click Configuration Logging.

    • Enable logging.

    • Select the storage pool for the log data on the Trellix Enterprise Security Manager - Enterprise Log Manager.

    • If you haven't selected the Trellix Enterprise Security Manager - Enterprise Log Manager for the log data, confirm that you want to do this.

      Note

      Once you make this association, you cannot change it.

    • If you have more than one Trellix Enterprise Security Manager - Enterprise Log Manager device, identify which one to use for the log data.

    • Select the IP address to communicate with the Trellix Enterprise Security Manager - Enterprise Log Manager.